NIST Cybersecurity Framework 2.0
Interactive implementation checklist for NIST CSF 2.0. Six functions with all categories and subcategories. Track your maturity — progress saved in your browser.
GV Govern
ID Identify
PR Protect
DE Detect
RS Respond
RC Recover
Related Compliance Frameworks
International ISMS standard — 93 controls across 4 themes. Widely recognised globally.
18 prioritised controls in 3 implementation groups. Practical cyber hygiene baseline.
12 requirements for entities handling payment card data. Mandatory for merchants and service providers.
Trust Service Criteria audit covering Security, Availability, Confidentiality, Integrity and Privacy.
India mandatory incident reporting: 6-hour reporting window, 180-day log retention, NTP sync.
Reserve Bank of India Master Directions covering cyber risk, SOC requirements and incident reporting.
Administrative, physical and technical safeguards for electronic Protected Health Information (ePHI).
Frequently Asked Questions
What is NIST CSF 2.0?
The 2024 update to the NIST Cybersecurity Framework, a voluntary framework for managing cybersecurity risk applicable to organisations of any size or sector.
What changed from NIST CSF 1.1 to 2.0?
CSF 2.0 added a sixth function, GOVERN, covering organisational context, risk strategy and oversight, and broadened scope beyond critical infrastructure to all organisations.
What are the six functions of NIST CSF 2.0?
GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER.
Is NIST CSF a certification?
No — unlike ISO 27001, there is no formal NIST CSF certification; organisations self-assess maturity and tiers against the framework's categories and subcategories.